CVE-2026-68130

Source
https://cve.org/CVERecord?id=CVE-2026-68130
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68130.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68130
Downstream
Published
2026-08-10T11:58:52Z
Modified
2026-08-25T03:51:43Z
Summary
ksmbd: defer destroy_previous_session() until after NTLM authentication
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: defer destroy_previous_session() until after NTLM authentication

In ntlm_authenticate(), destroy_previous_session() is called using a user pointer resolved from the client-supplied NTLM blob username field before the NTLMv2 response is validated. An authenticated attacker can set the NTLM blob username to match a victim account and set PreviousSessionId to the victim's session ID; destroy_previous_session() destroys the victim's session while ksmbd_decode_ntlmssp_auth_blob() subsequently rejects the request with -EPERM.

Move destroy_previous_session() and the prev_id assignment to after ksmbd_decode_ntlmssp_auth_blob() returns success and use sess->user rather than the pre-authentication lookup result. This matches the ordering already used by krb5_authenticate(), where destroy_previous_session() is called only after ksmbd_krb5_authenticate() returns success.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68130.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Fixed
ab0230257ebdf48b07eaa679a8c92bc842fe3498
Fixed
370b0ec8822b69c9073265e16b7daaa8201c9a4f
Fixed
5c833074b549e5db125436a6f681af682261f785
Fixed
243f1614ef2aca2d62a744575f1c24b07cd42757
Fixed
18705cace0619fd2123737dcd028147774f38181
Fixed
0ff12308c8a6c16ab68f0a487ffa93d69001dc18
Fixed
c74801ee524f477c174a1899782b6c3b6918d407

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68130.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.217
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68130.json"